PT-2020-2694 · Cisco · Cisco Ios Xe+6
Published
2020-06-03
·
Updated
2021-10-18
·
CVE-2020-3217
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IOS Software (affected versions not specified)
Cisco IOS XE Software (affected versions not specified)
Cisco IOS XR Software (affected versions not specified)
Cisco NX-OS Software (affected versions not specified)
Description
A vulnerability in the Topology Discovery Service of Cisco One Platform Kit (onePK) could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient length restrictions when the onePK Topology Discovery Service parses Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol message to an affected device, potentially causing a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges, or to cause a process crash, resulting in a reload of the device and a DoS condition.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Discovery Protocol
Cisco Ios
Cisco Ios Xe
Cisco Ios Xr
Cisco Nx-Os
Cisco Nexus
Cisco One Platform Kit